QID 91825
Date Published: 2021-10-13
QID 91825: Microsoft System Center Operations Manager (SCOM) Information Disclosure Vulnerability - October 2021
System Center Operations Manager (SCOM) is a cross-platform data center management system for operating systems and hypervisors.
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is file content.
Affected Software:
System Center 2019 Operations Manager
System Center 2016 Operations Manager
System Center 2012 R2 Operations Manager
NOTE:This vulnerability only affects machines that have the SCOM web console installed
QID Detection Logic (Authenticated):
TODO
Insecure Direct Object Reference (IDOR) vulnerability in APM websites that allows users to access any file under Web folder and gain access to the file contents.
Solution
Users are advised to check KB5006871 for more information.
Vendor References
- KB5006871 -
support.microsoft.com/en-us/help/5006871
CVEs related to QID 91825
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| KB5006871 |
|